5 ms·
> If desktop Linux ever gets around to this I don’t really understand what that means. Are you, or anyone, expecting a signed Linux kernel by some organization
by eddythompson80 9mo ago
> If desktop Linux ever gets around to this
I don’t really understand what that means. Are you, or anyone, expecting a signed Linux kernel by some organization (say Valve or Debian or whatever) that will be the “Gaming Kernel”? If not, no Linux kernel feature is safe from 1 patch and a custom build.
- charcircuit 9mo agoI mean the approach the article is talking about. Creating a safe hypervisor and safe kernel that games can get an attestation to in order to trust that they are running on a secure platform.
- eddythompson80 9mo agoYeah, then the “safe kernel” is Valve’s kernel.
- wmf 9mo agoMany people would be happy with a Valve gaming kernel.
- eddythompson80 9mo agoMany are happy with a Sony gaming kernel as is.
- oneshtein 9mo agoStock Linux kernel in Fedora, for example, is signed by MS, so SecureBoot allows to boot it without modification. Kernel booted by SecureBoot is locked down by default. To unlock it, you need to patch kernel source, rebuild it, sign it with your own key, and install this key via UEFI to boot it in SecureBoot mode. Your custom key will not pass remote attestation.
- eddythompson80 9mo agoThey are not signed by MS they are dual signed by a CA that MS runs as a service for UEFI secure boot as well as the distro’s CA. If you were around in the late 2000s when UEFI SecureBoot was being proposed, you’d remember the massive hysteria about how “SecureBoot is a MS plot to block Linux install”. Even though the proposal was to just allow the UEFI to verify the sig of the binary it’ll boot, and to allow the user to provide the UEFI with the keys to trust, the massive fear was that MB manufacturers will just be too lazy (or be bought by MS) that they will only allow MS keys, or that the process to enlist a new key would be too difficult to sufficiently discourage people from installing Linux (because you know, I’m all for the freedom and fuck-Microsoft camp, until its expected that I verify a signature) so Microsoft offered a service for CA service, like https CAs, but for boot signing. Assuming you’re a good Linux user, you can always just put your favorite distro signing key in your UEFI without accepting MS CA n there.
- barrkel 9mo agoWell if you walk backwards 10 paces and look at the big picture here, what MS did enables anti-cheat attestation via TPM, and that in turn can act as a feature that structurally - via the market - reduces the appeal of Linux. Signing your own custom-built kernel (if you need to adjust flags etc., like I do) won't result in a certification chain that will pass the kind of attestation being sketched out by the OP article here.
- eddythompson80 9mo agoYes because you’re trying to communicate that trust to other players of the game you’re playing as opposed to yourself. It’s why I hate the term “self-signed” vs “signed” when it comes to tls/https. I always try to explain to junior developers that there is no such a thing as “self-signed”. A “self-signed” certificate isn’t less secure than a “signed” certificate. You are always choosing who you want to trust when it comes to encryption. Out of convenience, you delegate that to the vendor of your OS or browser, but it’s always a choice. But in practice, it’s a very different equation.
- barrkel 9mo agoThe problem comes in when you need to flip a flag that isn't set in the default kernel build for compatibility with your hardware and configuration.
- eddythompson80 9mo agoExactly, then you are depending on that third party (be it MS, Apple, Valve, Debian, etc) to care enough about your obscure setup to support it.